// For flags

CVE-2019-5408

 

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier than 8.6.1-02 RepMgr if it is installed on the same machine as DevMgr TSMgr if it is installed on the same machine as DevMgr. The resolution is to upgrade to the fixed version as described below or later version of DevMgr 8.6.2-02 or later. RepMgr and TSMgr will be corrected by upgrading DevMgr.

Los productos Command View Advanced Edition (CVAE) contienen una vulnerabilidad que podría exponer la información de configuración de hosts y sistemas de almacenamiento administrados mediante el servidor Device Manager. Este problema es debido a una vulnerabilidad en la GUI del Administrador de Dispositivos. Los siguientes productos están afectados. DevMgr versiones 7.0.0-00 y anteriores a 8.6.1-02, RepMgr si está instalado en el mismo equipo que DevMgr, TSMgr si está instalado en el mismo equipo que DevMgr. La resolución es actualizar a versión corregida como se describe a continuación o versión posterior de DevMgr 8.6.2-02 o posterior. RepMgr y TSMgr serán corregidos mediante la actualización de DevMgr.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-04 CVE Reserved
  • 2019-08-09 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hp
Search vendor "Hp"
Xp7 Device Manager
Search vendor "Hp" for product "Xp7 Device Manager"
>= 7.0.0-00 < 8.6.1-02
Search vendor "Hp" for product "Xp7 Device Manager" and version " >= 7.0.0-00 < 8.6.1-02"
-
Affected
Hp
Search vendor "Hp"
Xp7 Replication Manager
Search vendor "Hp" for product "Xp7 Replication Manager"
--
Affected
Hp
Search vendor "Hp"
Xp7 Tiered Storage Manager
Search vendor "Hp" for product "Xp7 Tiered Storage Manager"
--
Affected